Answer in brief
CVE-2026-86237 records a Unknown severity vulnerability in openagents-org openagents http.py test_default_model server-side request forgery. The current sources do not mark it as known exploited. The current feed maps openagents-org/openagents (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps openagents-org/openagents (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| openagents-org/openagentsgeneric | 0.8.0 || 0.8.1 || 0.8.2 || 0.8.3 || 0.8.4 || 0.8.5 || 0.8.6 || 0.8.7 || 0.8.8 || 0.8.9 || 0.8.10 || 0.8.11 || 0.8.12 || 0.8.13 || 0.8.14 || 0.8.15 || 0.8.16 || 0.8.17 || 0.8.18 || 0.8.19 || 0.9.3.post20 | Not reported |
Published upstream
Sep 7, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 7, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 7, 2026
A vulnerability was found in openagents-org openagents up to 0.8.19/0.9.3.post20. Impacted is the function test_default_model of the file sdk/src/openagents/sdk/transports/http.py. Performing a manipulation of the argument base_url results in server-side request forgery. The attack may be initiated remotely. The exploit has been made public and could be used. Endpoint and both sinks unchanged since filing; only the file moved (e277dd1a). Maintainer closed as inapplicable yet the identical unguarded code still ships in 0.9.3.post20. Sibling admin endpoints do call the shipped-but-unused-by-this-handler _require_admin().
Quoted source text, attributed separately from HOL analysis.